CVE-2008-5687

MediaWiki <1.13.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47678
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33349

Scores

EPSS 0.0043
EPSS Percentile 63.0%

Details

CWE
CWE-264
Status published
Products (10)
mediawiki/mediawiki 1.11 (2 CPE variants)
mediawiki/mediawiki 1.11.1
mediawiki/mediawiki 1.11.2
mediawiki/mediawiki 1.12.0 (2 CPE variants)
mediawiki/mediawiki 1.12.1
mediawiki/mediawiki 1.12.2
mediawiki/mediawiki 1.12.3
mediawiki/mediawiki 1.13.0 (3 CPE variants)
mediawiki/mediawiki 1.13.1
mediawiki/mediawiki 1.13.2
Published Dec 19, 2008
Tracked Since Feb 18, 2026